AgentPit 财经综合分析
PassAudited by VirusTotal on Apr 22, 2026.
Findings (1)
The skill manages a service-specific API key by instructing the agent to write it to the local filesystem (~/.openclaw/secrets/agentpit.cpk) and use it for authenticated curl requests to api.agentpit.io. While the behavior appears aligned with the stated financial analysis purpose, the use of shell commands for secret persistence and external network access represents high-risk capabilities that warrant a suspicious classification under the provided criteria.
